tang
tang copied to clipboard
Similar protocol with proof
While investigating the security of McCallum-Relyea I found epeint.iacr.org/2016/144 which presents a similar protocol with a security proof and integrated with shamir secret sharing.
Migration would solve the issue of proveable security.
Corrected link: https://eprint.iacr.org/2016/144
There is also 2014/650
https://eprint.iacr.org/2018/733 is the most sophisticated in the series and integrates shamir secret sharing and has stateless servers. Not sure yet which makes the most sense but any of these could potentially work.